A standard architecture for TREs: why is it important in a federated world?
Abstract
Background The Standard Architecture for Trusted Research Environments (SATRE), version 1.0, provided a baseline set of best-practice capabilities of relevance to TREs in the UK developed jointly with TRE operators and public representatives. It has requirements that TREs holding personal data should fulfil to demonstrate equivalence in a transparent manner. It was published in October 2023 and was quickly adopted by Trusted Research Environments (TREs) across the UK and beyond. The initial success of SATRE was due to two main factors: it was driven by an open-collaboration with a grassroots community, and it encapsulated the existing state of most TREs, as opposed to imposing a top-down view of what a TRE should be. This was primarily achieved through Collaboration Cafés – open events that anyone can attend – supported by other events to obtain input and feedback from the wider community. Independent communities have used SATRE as a starting point for federation projects including the NHS regional SDEs, the Scottish Safe Haven network, and the European Open Source Cloud ENTRUST network of federated TREs. Others have also asked for extensions to SATRE such as for natural language processing, or data tiering and classification. Finally, several groups planning to deploy new TREs had requested guidance on how to implement a new SATRE compliant TRE. Objectives Version 2 of SATRE, through the TREvolution Core Programme, incorporates guidance on TRE federation for the UK and beyond. Supporting these needs is critical to ensuring the community remains involved in SATRE, and will not result in multiple competing or conflicting standards. It establishes a long-term sustainable governance and accreditation model. The new version also allows for infrastructure that was, and still is, under active development, with limited existing best-practice. This has required a different approach to that taken for version 1.0, with a layered specification model providing not only architectural but also implementation guidance. A significant outcome of the SATRE work is a specification for TREs based on Kubernetes; a popular, flexible and standard open-source platform for managing containerised workloads and services which is already making in-roads into the TRE ecosystem. Encouraging Kubernetes as a common – community owned – infrastructure baseline allows components to be shared across implementations where practical, and provides a solution for independent TREs to be part of a federated network. Finally, we provide an initial version of a technical specification-compliant vendor-neutral reference TRE, called “K8TRE”. This is suitable for pilot deployments, and development continues to make it production ready. K8TRE is fully open-source and can be deployed on private infrastructure, or in the public cloud, with minimal adaptation.